Systems and methods for extracting browser-obtained device information for authenticating user devices
Abstract
A device authentication computing device for authenticating consumer computing devices used to perform online payment transactions is provided. The device authentication computing device receives cardholder device information for each of a plurality of cardholder computing devices of a cardholder and stores the cardholder device information based on a unique identifier associated with the cardholder. During an online transaction using a consumer computing device, the device authentication computing device receives an authentication request message and a unique identifier associated with the cardholder. The device authentication computing device also receives, via an Internet browser, transaction device information corresponding to the consumer computing device. The device authentication computing device compares the device information received during the transaction to the stored cardholder device information. Based on the comparison, the device authentication computing device transmits an authentication response message to the merchant indicating whether the transaction device information matches stored cardholder device information.
Claims
exact text as granted — not AI-modified1 . A device authentication computing device, said device authentication computing device comprising one or more processors in communication with one or more memory devices, said device authentication computing device configured to:
receive cardholder device information for each of a plurality of cardholder computing devices of a cardholder; store the cardholder device information based on a unique identifier associated with the cardholder; receive an authentication request message requesting that a consumer computing device be authenticated as an authenticatable cardholder computing device; receive, via an Internet browser of the consumer computing device, transaction device information corresponding to the consumer computing device; receive a unique identifier associated with the cardholder; retrieve the stored cardholder device information based on the unique identifier; compare the stored cardholder device information with the transaction device information; and transmit an authentication response message, either directly or indirectly, to the merchant, the authentication response message indicating whether the transaction device information matches the stored cardholder device information.
2 . The device authentication computing device of claim 1 , wherein comparing the stored cardholder device information with the transaction device information further comprises determining whether the stored cardholder device information matches the transaction device information beyond a predetermined match threshold.
3 . The device authentication computing device of claim 1 , wherein the transaction device information and the stored cardholder device information correspond to at least one of a browser engine name, a screen color depth, a system operating system, a system CPU, a system platform, a browser name, a browser engine version, a browser version, a user agent, an operating system, a platform, a screen width, a screen height, a system language, a time zone, a hypertext transfer protocol header, a browser language, an installed cookie, and an installed plugin.
4 . The device authentication computing device of claim 1 , wherein comparing the transaction device information and the stored device information further comprises at least one of: (i) matching a first hash value derived from the transaction device information to a second hash value derived from the stored device information; (ii) matching high entropy device information of the transaction device information to high entropy device information of the stored device information; (iii) matching medium entropy device information of the transaction device information to medium entropy device information of the stored device information; and (iv) matching low entropy device information of the transaction device information to low entropy device information of the stored device information.
5 . The device authentication computing device of claim 1 further configured to transmit a transaction data request message configured to cause the consumer computing device to capture the transaction device information and to transmit the transaction device information to the device authentication computing device.
6 . The device authentication computing device of claim 1 further configured to update at least a portion of the stored cardholder device information by replacing the portion of the stored cardholder device information with a corresponding portion of the transaction device information.
7 . The device authentication computing device of claim 1 , wherein the cardholder device information is received during a device registration process.
8 . The device authentication computing device of claim 1 further configured to generate and transmit a fraud alert when the transaction device information does not match the stored cardholder device information beyond a predetermined match threshold.
9 . The device authentication computing device of claim 1 , wherein the authentication response message advises the merchant that the consumer computing device is one of the authenticated cardholder computing devices, and wherein said device authentication computing device is further configured to prompt a merchant computing device to complete a payment transaction associated with the authentication request message that was initiated by the cardholder using the one authenticated cardholder computing device.
10 . A computer-implemented method for authenticating a user computing device during an online payment transaction, said method implemented using a device authentication computing device in communication with one or more memory devices, said method comprising:
receiving cardholder device information for each of a plurality of cardholder computing devices of a cardholder; storing the cardholder device information based on a unique identifier associated with the cardholder; receiving an authentication request message requesting that a consumer computing device be authenticated as an authenticatable cardholder computing device receiving, via an Internet browser of the consumer computing device, transaction device information corresponding to the consumer computing device; receiving a unique identifier associated with the cardholder; retrieving the stored cardholder device information based on the unique identifier; comparing the stored cardholder device information with the transaction device information; and transmitting an authentication response message, either directly or indirectly, to the merchant, the authentication response message indicating whether the transaction device information matches the stored cardholder device information.
11 . The method of claim 10 further comprising determining whether the stored cardholder device information matches the transaction device information beyond a predetermined match threshold.
12 . The method of claim 10 , wherein the transaction device information and the stored cardholder device information correspond to at least one of a browser engine name, a screen color depth, a system operating system, a system CPU, a system platform, a browser name, a browser engine version, a browser version, a user agent, an operating system, a platform, a screen width, a screen height, a system language, a time zone, a hypertext transfer protocol header, a browser language, an installed cookie, and an installed plugin.
13 . The method of claim 10 , wherein comparing the transaction device information and the stored device information further comprises at least one of: (i) matching a first hash value derived from the transaction device information to a second hash value derived from the stored device information; (ii) matching high entropy device information of the transaction device information to high entropy device information of the stored device information; (iii) matching medium entropy device information of the transaction device information to medium entropy device information of the stored device information; and (iv) matching low entropy device information of the transaction device information to low entropy device information of the stored device information.
14 . The method of claim 10 further comprising updating at least a portion of the stored device information by replacing the portion of the stored device information with a corresponding portion of the transaction device information.
15 . The method of claim 10 , further comprising generating and transmitting a fraud alert when the transaction device information does not match the stored cardholder device information beyond a predetermined match threshold.
16 . A computer-readable storage medium having computer-executable instructions embodied thereon, wherein when executed by a device authentication computing device having one or more processors in communication with one or more memory devices, the computer-executable instructions cause the device authentication computing device to:
receive cardholder device information for each of a plurality of cardholder computing devices of a cardholder; store the cardholder device information based on a unique identifier associated with the cardholder; receive an authentication request message requesting that a consumer computing device be authenticated as an authenticatable cardholder computing device receive, via an Internet browser of the consumer computing device, transaction device information corresponding to the consumer computing device; receive a unique identifier associated with the cardholder; retrieve the stored cardholder device information based on the unique identifier; compare the stored cardholder device information with the transaction device information; and transmit an authentication response message, either directly or indirectly, to the merchant, the authentication response message indicating whether the transaction device information matches the stored cardholder device information.
17 . The computer-readable storage medium of claim 16 , wherein the computer-executable instructions cause the device authentication computing device to determine whether the stored cardholder device information matches the transaction device information beyond a predetermined match threshold.
18 . The computer-readable storage medium of claim 16 , wherein the transaction device information and the stored device information include at least one of a browser engine name, a screen color depth, a system operating system, a system CPU, a system platform, a browser name, a browser engine version, a browser version, a user agent, an operating system, a platform, a screen width, a screen height, a system language, a time zone, a hypertext transfer protocol header, a browser language, an installed cookie, and an installed plugin.
19 . The computer-readable storage medium of claim 16 , wherein the computer-executable instructions cause the device authentication computing device to compare the transaction device information to the stored device information by performing at least one: (i) matching a first hash value derived from the transaction device information to a second hash value derived from the stored device information;
(ii) matching high entropy device information of the transaction device information to high entropy device information of the stored device information; (iii) matching medium entropy device information of the transaction device information to medium entropy device information of the stored device information; and (iv) matching low entropy device information of the transaction device information to low entropy device information of the stored device information.
20 . The computer-readable storage medium of claim 16 , wherein the computer-executable instructions cause the device authentication computing device to calculate a similarity score representing a degree of similarity between the transaction device information and the stored device information corresponding to at least one of the plurality of cardholder computing devices.
21 . The computer-readable storage medium of claim 16 , wherein the computer-executable instructions cause the device authentication computing device to update at least a portion of the stored cardholder device information by replacing the portion of the stored cardholder device information with a corresponding portion of the transaction device information.Join the waitlist — get patent alerts
Track US2017316415A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.